PT-2025-5266 · Coolify · Coolify

Angelej

·

Published

2025-01-24

·

Updated

2025-01-31

·

CVE-2025-24025

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Coolify versions prior to 4.0.0-beta.380
Description Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. The issue arises when the tags page allows users to search for tags. If the search does not return any results, the query gets reflected on the error modal, leading to cross-site scripting.
Recommendations For versions prior to 4.0.0-beta.380, update to version 4.0.0-beta.380 to resolve the issue. As a temporary workaround, consider restricting access to the tags page or disabling the search functionality until the update is applied.

Exploit

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2025-24025
GHSA-F2GF-JVMH-VQ73

Affected Products

Coolify